Junglewise Threat Intelligence

CVE-2026-83202: Oracle Siebel CRM Deployment authentication bypass in Server Infrastructure

CVE-2026-83202 · Severity: critical · CVSS 9.1 · Published 2026-09-15

Technologies: Oracle Siebel CRM Deployment, Oracle Siebel CRM. Vendors: Oracle.

Executive brief

Oracle Siebel CRM is a customer relationship management platform used by enterprises to manage customer interactions and business data. This vulnerability allows unauthenticated attackers with network access to bypass authentication and gain unauthorized access to read, modify, or delete critical customer data and business information stored in Siebel CRM. A successful exploit could result in complete compromise of sensitive business data and customer information without requiring any valid credentials.

Technical details

This vulnerability in the Siebel CRM Deployment Server Infrastructure component is an authentication bypass affecting versions 17.0 through 26.7. The flaw is easily exploitable via HTTP network access without authentication (PR:N, UI:N). An unauthenticated attacker can achieve high-impact confidentiality and integrity violations, allowing unauthorized creation, deletion, modification, and reading of critical data accessible through the Siebel CRM Deployment system. The CVSS 3.1 vector indicates no availability impact, but full confidentiality and integrity compromise is possible. Patch status and detailed remediation guidance should be obtained from Oracle's official security advisories.

Affected products

  • Oracle Siebel CRM Deployment 17.0-26.7

Timeline

  • 2026-09-15: disclosed

References

Related threats